Back to skill

Security audit

宏观脉搏

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent macro-news monitoring bot, but it asks for scheduled automated browsing, local write-backs, and outbound report delivery that are not fully reflected in its declared tool metadata.

Review this before installing if you do not want an automated daily agent that browses financial websites, modifies local skill reference/report files, and sends reports to IM, email, or webhooks. Configure delivery targets deliberately, and prefer explicit manual triggering or an opt-in schedule unless you want recurring pushes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest declares only read and exec/browser-style tooling, but the workflow also instructs use of a message tool and external delivery channels. This creates a capability-transparency gap: users or policy layers may approve the skill believing it cannot transmit data externally, while the documented behavior includes outbound messaging and webhook delivery.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger keywords are broad terms like 宏观, cpi, pmi, 利率, and fred, which can match ordinary finance-related conversations outside the user's intent to invoke this skill. In an automated agent environment, overbroad activation can cause unintended browsing, data collection, file updates, and outbound pushes.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill specifies automatic push delivery to IM/email/webhook and a fallback that persists reports locally, but it does not clearly warn users that content may be transmitted off-platform or stored on disk. This can expose potentially sensitive user-configured targets, report contents, and operational metadata without informed consent.

Missing User Warnings

Low
Confidence
86% confidence
Finding
The skill automatically writes back to local knowledge-base and source-health files, but it does not clearly inform users that local files will be modified. Unannounced file mutation can create integrity issues, especially because content is derived from external web sources and may pollute future runs.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.